Skip to content

Responsible AI resourceMenuHomeModel policyDecisionsResearch & approachGet support

Leadership guide/Ten strengthening opportunities

Ten strengthening opportunities

Make the principle
work under pressure.

Use these ten questions to find where a policy needs a clearer decision, a stronger safeguard or evidence that its promises work.

In this guideTen opportunitiesDisciplines beyond higher edHow to prioritizeThese are HumanSkills improvement opportunities, not measured claims that most peer institutions omit them. The starting commitments reflect the cited policy themes; the operational tests below help you assess your own material.Data privacyProcurement and vendorsConsequential decisionsConnected actionsHuman capabilityLearning and workforce preparationAccess and student supportIncidents and correctionBoard and leadership assuranceMonitoring and renewalData privacy

1. Protect the whole information journey.

Starting commitment: Restrict protected information in unapproved AI tools.

The gap to test: A rule about prompts can leave retrieval, transcripts, inferred information, outputs, logs and deletion unresolved.

How to strengthen itDocument the full information flow. Specify who may access it, what the vendor may reuse, when it must be deleted and what happens after a material change.

What good looks like: An approved data-flow record plus checked access, retention, deletion and vendor conditions.

Bring in: Privacy, information security, records, procurement and the service owner.

Supporting discipline: Voluntary AI risk guidance ↗. See the scope notes below.

Work through the campus decision→Procurement and vendors

2. Make approval specific and renewable.

Starting commitment: Use institutionally approved products.

The gap to test: Product approval can be mistaken for permission to use every feature with any information.

How to strengthen itApprove the use, information and permissions. Record review triggers, service-provider responsibilities and an exit route when terms or capability change.

What good looks like: A use-specific approval with vendor evidence, conditions and a renewal owner.

Bring in: Procurement, IT, information security and the accountable unit.

Supporting discipline: Information-security operations ↗. See the scope notes below.

Work through the campus decision→Consequential decisions

3. Test whether human review changes the outcome.

Starting commitment: Keep a person responsible for AI-supported work.

The gap to test: A person can approve an output without the expertise, time or authority to challenge it.

How to strengthen itUse difficult cases to establish whether reviewers identify material errors, explain their reasoning and exercise the authority to stop or correct the result.

What good looks like: Observed reviewer performance, escalation records and a usable reconsideration route.

Bring in: The accountable service leader and qualified reviewers.

Supporting discipline: Safety-critical human factors ↗. See the scope notes below.

Work through the campus decision→Connected actions

4. Define what an AI system may actually do.

Starting commitment: Require responsible use and human accountability.

The gap to test: Permission to draft does not settle authority to send a message, change a record, access another system or spend.

How to strengthen itSet task-specific access, permitted actions, confirmation points and limits. Test interruption, rollback where feasible and recovery before expanding authority.

What good looks like: A documented action boundary and a demonstrated stop-and-recovery exercise.

Bring in: System owner, information security and the deciding authority.

Supporting discipline: Voluntary AI risk guidance ↗. See the scope notes below.

Work through the campus decision→Human capability

5. Make readiness part of permission.

Starting commitment: Provide AI guidance and training.

The gap to test: Attendance or tool familiarity does not demonstrate readiness for consequential responsibilities.

How to strengthen itDefine what each role must be able to do. Provide practice, feedback, appropriate assessment and a support route. Revisit readiness as the task changes.

What good looks like: Role-specific capability expectations and evidence of performance on representative tasks.

Bring in: Academic leaders, learning and development, supervisors and service owners.

Supporting discipline: Governance and capability ↗. See the scope notes below.

Work through the campus decision→Learning and workforce preparation

6. Show what the student can do.

Starting commitment: Explain permitted assistance and protect academic integrity.

The gap to test: A polished submission can conceal whether the learner can reason, perform safely or transfer understanding to work.

How to strengthen itDefine independent and AI-supported performances. Use explanations, demonstrations and unfamiliar situations to assess the intended learning.

What good looks like: Assessment criteria connected to learning outcomes and relevant occupational tasks.

Bring in: Faculty, program leaders and employer advisers within academic authority.

HumanSkills implementation recommendation, informed by the teaching and capability chapters.

Work through the campus decision→Access and student support

7. Test the route to a person.

Starting commitment: Commit to equitable access and human oversight.

The gap to test: A nominal support contact may not work for evening learners, people using assistive technology or people facing unusual circumstances.

How to strengthen itTest realistic support journeys with relevant users. Confirm staffing, response expectations, accommodations and an alternative when the service cannot help.

What good looks like: Completed support and accessibility tests with unresolved barriers assigned to an owner.

Bring in: Student services, accessibility, IT and the service owner.

Supporting discipline: Safety-critical human factors ↗. See the scope notes below.

Work through the campus decision→Incidents and correction

8. Plan how to repair harm.

Starting commitment: Report AI concerns and security incidents.

The gap to test: Reporting does not explain how affected people obtain correction or how the institution contains a continuing problem.

How to strengthen itRehearse a case from detection through containment, communication, record correction and an authorized restart. Coordinate existing incident and appeal processes.

What good looks like: A completed exercise with named responsibilities and follow-up actions.

Bring in: Incident leads, responsible offices and the accountable executive.

Supporting discipline: Information-security operations ↗. See the scope notes below.

Work through the campus decision→Board and leadership assurance

9. Give leadership evidence of performance.

Starting commitment: Assign governance roles and review the policy.

The gap to test: An annual policy update can leave leaders without evidence about current uses, unresolved risks or the effect on people.

How to strengthen itAgree a concise reporting set: significant uses and owners, outcomes, material incidents, unresolved conditions and decisions needing authority or resources.

What good looks like: A recurring assurance report grounded in current institutional records.

Bring in: Executive sponsor, service owners and the appropriate governing body.

Supporting discipline: Financial-services model governance ↗. See the scope notes below.

Work through the campus decision→Monitoring and renewal

10. Make continuation a decision.

Starting commitment: Review AI policies periodically.

The gap to test: A pilot can become permanent even when its original assumptions, staffing or vendor conditions have changed.

How to strengthen itSet review dates and event triggers. Compare results with the intended purpose, document limitations and decide to continue, change, restrict or retire the use.

What good looks like: A dated continuation decision supported by outcome evidence and current conditions.

Bring in: Deployment owner and approving authority.

Supporting discipline: Financial-services model governance ↗. See the scope notes below.

Work through the campus decision→

Borrow mature disciplines with care.

Useful practices also come from information security, financial-services model governance and safety-critical human factors. We translate those disciplines into campus questions. We retain source notes so the recommendations remain traceable.

Voluntary AI risk guidance

Examine data exposure, connected components and risks that change with the use. Suggested actions help turn principles into operating checks.

Scope: A voluntary profile, not an institutional certification or a complete legal checklist.

NIST: Generative AI Profile ↗

Governance and capability

Connect assigned responsibilities to the skills, resources and training needed to carry them out.

Scope: Adapt the suggested actions to institutional roles and the consequences of the use.

NIST: AI RMF Playbook: Govern ↗

Financial-services model governance

Use proportionate validation, outcome monitoring, inventories and clear responsibility to understand whether a system remains fit for its intended purpose.

Scope: Banking guidance. It expressly excludes generative and agentic AI from its scope. We borrow governance disciplines by analogy; we do not present it as a campus or generative-AI requirement.

Federal Reserve, OCC and FDIC: Revised Guidance on Model Risk Management, SR 26-2 ↗

Information-security operations

Translate protection into assigned ownership, risk assessment, access controls, service-provider oversight and incident arrangements.

Scope: Some institutions have relevant obligations already. Determine coverage with responsible specialists; do not treat a legal requirement as an optional enhancement where it applies.

Federal Trade Commission: Safeguards Rule guidance ↗

Safety-critical human factors

Examine whether intended users can perform important tasks in the actual use environment, including foreseeable errors.

Scope: Medical-device guidance. The campus application is our adaptation of a testing discipline, not an FDA requirement for ordinary educational AI.

US Food and Drug Administration: Applying Human Factors and Usability Engineering to Medical Devices ↗

Choose the improvements that change an outcome.

Begin with consequential uses, protected information and controls that no one can demonstrate. Then work on unclear authority, support and capability. Avoid treating all ten opportunities as equally urgent.

For each improvement, name the affected use, evidence needed, responsible owner and decision date. Test it in a scenario before considering it complete.

Plan the task force’s work→Apply the review standard→

A conversation when it would helpWork through
a stronger safeguard.

If an outside perspective would help your team resolve a difficult choice, review a draft or plan capability building, talk with HumanSkills. We can help you define a useful, bounded next step.

Talk through the work→

Institutional decisions and approval remain with your team.